Critical Flaws Found in Four VS Code Extensions with Over 125 Million Installs
ID: c50d8b6a-d850-5afb-b4a8-11d766d950aa
STIX ID: report--c50d8b6a-d850-5afb-b4a8-11d766d950aa
Feed Name: The Hacker News
Security researchers disclosed multiple high-severity vulnerabilities in four widely used VS Code extensions (Live Server, Code Runner, Markdown Preview Enhanced, Microsoft Live Preview) that can lead to local file exfiltration and remote code execution. Three CVEs are listed (highest CVSS 9.1) and remain unpatched for the affected extensions, while Microsoft Live Preview was silently fixed; the extensions have a combined installation base of over 125 million, and exploitation scenarios include malicious webpages and social engineering. Recommendations include removing/uninstalling untrusted extensions, disabling localhost services, restricting network access, and keeping extensions updated.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
